Cloud & Infrastructure
Someone whose job it is to notice before your customers do
Most small businesses discover the state of their server management on the worst possible day. The site is down, the last backup is three weeks old, and the developer who set it up left in 2023. This is the service that means that day does not happen.
Indicative
From £250/month
Fixed price agreed in writing before any build starts.
Get a quote+44 7488 265083The problem this solves
A server nobody owns degrades quietly. Security updates go unapplied, disks fill, certificates expire on a Sunday, and backups run into a bucket nobody has ever restored from — which means, in practice, that there are no backups. None of this shows up until it all shows up at once.
What you get
Security patching on a schedule
OS and package updates applied monthly, with critical CVEs handled inside 72 hours. Applied to staging first where you have one, so a patch cannot be the thing that breaks you.
Backups that have been restored
Automated off-server backups with a documented retention period, and a real restore performed quarterly. A backup nobody has restored is a hypothesis, not a backup.
Uptime and certificate monitoring
External checks every minute, TLS certificates watched with 30 days’ notice, and domain expiry tracked — a lapsed domain has taken more sites offline than any hack.
Resource headroom
Disk, memory, CPU and database growth trended, so capacity is a planned purchase rather than an outage. Full disks remain one of the most common causes of a site going down.
Hardened configuration
SSH keys only, firewall rules reviewed, fail2ban, no unnecessary services listening, and admin panels behind IP restriction where practical.
A monthly report you can read
What was patched, what alerted, what was restored, and anything that needs a decision. Written in English, not as a dashboard export.
How we work
Inventory
Everything running: services, cron jobs, databases, certificates, DNS, and which of them anyone still needs. This step alone usually finds something surprising.
Risk report
What is unpatched, unmonitored or unbacked-up, ordered by what would hurt most. You get this in writing whether or not you continue.
Stabilise
Backups, monitoring and the urgent patches first. Days, not weeks.
Harden
Access, firewall and configuration tightened, with each change documented.
Routine operation
Monthly patching, quarterly restore tests, and alerts routed to a real person.
Quarterly review
Capacity, cost and anything approaching end of life.
What you should expect
- Backups proven by restore, not assumed
- Security patches applied on a schedule instead of after an incident
- Outages detected in minutes by monitoring, not hours by customers
- One named contact who already knows how your server is built
Built with
- Ubuntu
- Debian
- AlmaLinux
- CloudLinux
- Nginx
- Apache
- LiteSpeed
- MySQL
- MariaDB
- PostgreSQL
- Redis
- cPanel
- Plesk
- Cloudflare
- Let’s Encrypt
- Imunify360
Mainstream, well-supported technology — chosen so you can hire for it and so another team could take the project over.
Server Management — your questions
Including the ones about cost, which most agencies leave off the page.
From around £250 per month for a single well-behaved server, rising with the number of servers and the response time you need. We quote after the inventory step, because quoting before knowing what is running is guesswork.
Partly. On shared hosting the provider patches the OS, so the value is in monitoring, backups you control, certificate and domain expiry, and application-level updates. We will tell you honestly if your host already covers enough that you do not need us.
Monitoring alerts us within a minute. Under a business-hours agreement we act at the start of the next working day; under out-of-hours cover we act immediately. We are explicit about which you are buying, because the difference is the entire value of the service.
Yes, and the handover is the part we plan most carefully. We document what exists before changing anything, so if access is lost or credentials turn out to be wrong there is a written record to work from.
Yes. The order is: contain, preserve evidence, find how they got in, then clean and patch. Restoring a backup without finding the entry point simply restores the vulnerability — we have seen sites reinfected within hours that way.
Related services
Most projects touch more than one of these.
DevOps & Cloud Engineering
Automated pipelines, infrastructure defined in code, and monitoring that tells you about a problem before a customer does.
Read moreSecurity Audits & Hardening
A manual audit with working proof of concept for each finding, a prioritised fix plan, and a retest that confirms it.
Read moreCloud Migration
A phased migration with a rehearsed cutover and a rollback that has been tested, not just written down.
Read moreWordPress Development
Custom themes, plugin surgery, and performance and security work — plus a straight answer about whether to stay on WordPress.
Read moreWeb Development
Custom websites and web applications engineered for speed, search visibility and long-term maintainability.
Read moreTalk to someone who has built this before
A short call is usually enough to tell you whether this is the right service for your situation — including when it is not.
